Vulnerability index

Browse CVEs

6,380 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Wsr 1166dhp4 Firmware HIGH 8.8
CVE-2021-20731

WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands with root pr…

Fix: after 1.16
Fix from $1,950 2021-06-09
Bdr Suite CRITICAL 9.8
CVE-2021-26472

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using th…

Fix: 4.2.0.1+
Fix from $2,300 2021-06-08
Reg Keygen Git Hash CRITICAL 9.8
CVE-2021-32673

reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin throu…

Fix: after 0.10.15
Fix from $2,300 2021-06-08
Roon Server HIGH 7.2
CVE-2021-28811

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerabi…

Fix: 2021-05-18+
Fix from $1,950 2021-06-08
Common Services Platform Collector HIGH 7.2
CVE-2021-1538

A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to ex…

Fix: 2.9.1+
Fix from $1,950 2021-06-04
Fortiai Firmware HIGH 8.8
CVE-2021-24023

An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the…

Fix: after 1.4.0
Fix from $1,950 2021-06-03
Video Station HIGH 8.8
CVE-2021-28812

A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attac…

Fix: 5.5.4+
Fix from $1,950 2021-06-03
Fortiweb HIGH 8.8
CVE-2021-22123EPSS 77%

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote aut…

Fix: 6.2.4 / 6.3.8+
Fix from $1,950 2021-06-01
Bigtree Cms HIGH 8.8
CVE-2020-26670

A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a …

Fix: after 4.4.10
Fix from $1,950 2021-06-01
Pglogical MEDIUM 6.7
CVE-2021-3515

A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server…

Fix: 2.3.4 / 3.6.26+
Fix from $1,600 2021-06-01
Wp Super Cache HIGH 7.2
CVE-2021-24312

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of …

Fix: 1.7.3+
Fix from $1,950 2021-06-01
Network Security Manager HIGH 8.8
CVE-2021-20026EPSS 12%

A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. T…

Fix: 2.2.0+
Fix from $1,950 2021-05-27
750 893 Firmware MEDIUM 5.3
CVE-2021-30187

CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.

Mitigation only
Fix from $1,600 2021-05-25
Eyesofnetwork HIGH 8.8
CVE-2021-33525EPSS 8%

EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to…

Fix: after 5.3-11
Fix from $1,950 2021-05-24
Opened CRITICAL 9.8
CVE-2021-29300

The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands o…

Fix: 1.5.2+
Fix from $2,300 2021-05-24
Security Guardium HIGH 7.2
CVE-2021-20557

IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted req…

Patch available
Fix from $1,950 2021-05-24
Evolved Programmable Network Manager HIGH 8.8
CVE-2021-1487

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an aut…

Fix: 3.9 / 5.1+
Fix from $1,950 2021-05-22
Dna Spaces\ MEDIUM 6.7
CVE-2021-1557

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary comma…

Fix: 2.3.1+
Fix from $1,600 2021-05-22
Dna Spaces\ MEDIUM 6.7
CVE-2021-1558

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary comma…

Fix: 2.3.1+
Fix from $1,600 2021-05-22
Dna Spaces\ HIGH 7.2
CVE-2021-1559

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affe…

Fix: 2.0.519+
Fix from $1,950 2021-05-22
Dna Spaces\ HIGH 7.2
CVE-2021-1560

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affe…

Fix: 2.0.519+
Fix from $1,950 2021-05-22
Gc108p Firmware CRITICAL 9.8
CVE-2021-33514EPSS 8%

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a…

Fix: 1.0.2.3 / 1.0.4.3+
Fix from $2,300 2021-05-21
Rfntps Firmware MEDIUM 6.8
CVE-2021-20719

RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network segment to execute arbitrary…

Mitigation only
Fix from $1,600 2021-05-20
Webpanel CRITICAL 9.8
CVE-2021-31324EPSS 34%

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

No fix yet
Fix from $2,300 2021-05-18
Websvn CRITICAL 9.8
CVE-2021-32305EPSS 87%

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

Fix: 2.6.1+
Fix from $2,300 2021-05-18
Malware Remover MEDIUM 6.7
CVE-2020-36198

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote att…

Fix: 4.6.1.0+
Fix from $1,600 2021-05-13
Zzzphp CRITICAL 9.8
CVE-2021-32605

zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, …

Fix: 2.0.4+
Fix from $2,300 2021-05-11
Teamcity CRITICAL 9.8
CVE-2021-31915

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

Fix: 2020.2.4+
Fix from $2,300 2021-05-11
Big Ip Access Policy Manager HIGH 8.2
CVE-2021-23012

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items u…

Fix: 13.1.4 / 14.1.4+
Fix from $1,950 2021-05-10
Localstack CRITICAL 9.8
CVE-2021-32090

The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.

No fix yet
Fix from $2,300 2021-05-07